Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Webex Meetings Online MEDIUM 5.3
CVE-2019-15987

A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Ce…

Mitigation only
Fix from $1,600 2019-11-26
Plant Connect CRITICAL 9.8
CVE-2019-18250

In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, wh…

Mitigation only
Fix from $2,300 2019-11-26
Symantec Critical System Protection CRITICAL 9.8
CVE-2019-18374

Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a …

Mitigation only
Fix from $2,300 2019-11-25
Thinpro Linux MEDIUM 6.8
CVE-2019-16286

An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to la…

No fix yet
Fix from $1,600 2019-11-22
Client Proxy HIGH 8.6
CVE-2019-3654

Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning …

Fix: 3.0.0+
Fix from $1,950 2019-11-22
Wolfssl HIGH 7.5
CVE-2014-2904

wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

Fix: 3.2.0+
Fix from $1,950 2019-11-21
Freepbx CRITICAL 9.8
CVE-2019-19006 KEVEPSS 37%

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

Fix: after 15.0.16.26
Fix from $2,300 2019-11-21
Gs1900 8 Firmware CRITICAL 9.1
CVE-2019-15803

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented fun…

Fix: 2.50+
Fix from $2,300 2019-11-14
Wndr4700 Firmware CRITICAL 9.8
CVE-2013-3072

An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that w…

No fix yet
Fix from $2,300 2019-11-14
Baseboard Management Controller Firmware HIGH 7.8
CVE-2019-11170

Authentication bypass in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclo…

Fix: 2.18+
Fix from $1,950 2019-11-14
Tew 691gr Firmware CRITICAL 9.8
CVE-2013-3367

Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a value of …

Mitigation only
Fix from $2,300 2019-11-13
Taurus Al00b Firmware HIGH 8.8
CVE-2019-5233

Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploit…

Fix: after 10.0.0.41
Fix from $1,950 2019-11-13
Json Jwt HIGH 7.5
CVE-2019-18848

The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.

Fix: 1.11.0+
Fix from $1,950 2019-11-12
TYPO3 CRITICAL 9.8
CVE-2011-4628

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a …

Fix: 4.3.12 / 4.4.9+
Fix from $2,300 2019-11-06
Magento MEDIUM 6.5
CVE-2019-8108

Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authen…

Fix: 2.2.10 / 2.3.2+
Fix from $1,600 2019-11-05
Fedora MEDIUM 5.9
CVE-2013-5123EPSS 8%

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perfo…

Fix: 1.5+
Fix from $1,600 2019-11-05
Enterprise Chat And Email MEDIUM 6.5
CVE-2019-1877

A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through…

No fix yet
Fix from $1,600 2019-11-05
Firepower Services Software For Asa MEDIUM 5.3
CVE-2019-1980

A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco …

Fix: after 2.9.14.5
Fix from $1,600 2019-11-05
Fastgate Firmware HIGH 7.5
CVE-2019-18661

Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achi…

No fix yet
Fix from $1,950 2019-11-02
Airlink Es450 Firmware HIGH 7.1
CVE-2018-4064EPSS 14%

An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. …

No fix yet
Fix from $1,950 2019-10-31
Dvr 04ch Firmware HIGH 7.5
CVE-2013-1391EPSS 76%

Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allo…

No fix yet
Fix from $1,950 2019-10-30
Ip Security Camera Firmware CRITICAL 9.8
CVE-2016-2359

Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously ma…

Fix: after 2016-11-14
Fix from $2,300 2019-10-25
Yale Bluetooth Key MEDIUM 6.5
CVE-2019-17627

The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one au…

No fix yet
Fix from $1,600 2019-10-16
Vsa MEDIUM 6.7
CVE-2019-14510

An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdm…

Fix: after 9.5.0.22
Fix from $1,600 2019-10-11
Explorer 710 Firmware CRITICAL 9.8
CVE-2019-9531

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthe…

Mitigation only
Fix from $2,300 2019-10-10
Ac1450 Firmware HIGH 8.1
CVE-2019-17372

Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can th…

No fix yet
Fix from $1,950 2019-10-09
Ubuntu Linux CRITICAL 9.1
CVE-2019-17134

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass cli…

Fix: 2.1.2 / 3.2.0+
Fix from $2,300 2019-10-08
Db01 S Firmware CRITICAL 9.8
CVE-2019-13336

The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, bec…

No fix yet
Fix from $2,300 2019-10-08
Auth0.net HIGH 7.5
CVE-2019-16929

Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.

Fix: after 6.5.3
Fix from $1,950 2019-10-08
Firefox CRITICAL 9.8
CVE-2019-11733

When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found …

Fix: 68.0.2+
Fix from $2,300 2019-09-27